Wanchain's Cardano-BNB Bridge was exploited due to a cryptographic vulnerability in its TreasuryCheck validator, known as non-injective signed-message encoding. This flaw allowed multiple withdrawal requests to generate the same encrypted message, enabling an attacker to reuse a legitimate signature to authorize fraudulent transactions. As a result, approximately 515 million NIGHT tokens, valued at $9 million, were drained from the bridge's treasury. The stolen tokens were subsequently laundered into ADA on the Cardano network. Wanchain has since halted the bridge and confirmed the incident was isolated, not affecting Midnight's network or Cardano's core blockchain. This exploit is part of a series of recent attacks on cross-chain protocols, though overall crypto losses have reportedly declined year-over-year.
ambcrypto9天前




